Customize your website

Another nasty worm



Todd Musseau
Published on Febuary 2nd, 2009
Published on June 28th, 2010
Todd Musseau RSS Feed

Did you hear that another nasty worm is making its way around the internet?

Know as Conficker or Downadup, it first started showing up last October, and this guy is said to be able to do some interesting things.

It has been said that it, or one of its variations, can disable Windows update and defender. It will block your computer from accessing anti-virus websites and will attempt to steal your administrator password.

Topics :
Microsoft

Tech tips - Did you hear that another nasty worm is making its way around the internet?

Know as Conficker or Downadup, it first started showing up last October, and this guy is said to be able to do some interesting things.

It has been said that it, or one of its variations, can disable Windows update and defender. It will block your computer from accessing anti-virus websites and will attempt to steal your administrator password.

It attempts to obtain the IP address of the computer it is on from whatsmyipaddress.com (or other such websites). It starts a web server on the computer to host a copy of itself, and scans for other computers that might be on your network attempting to infect them as well. There have even been reports of it scheduling tasks on the infected computer to re-infect if the computer is cleaned.

Oh, don't forget, it can copy itself to your usb sticks and camera. I guess its real purpose is to give hackers a wide open door to your machine for financial gain.

Sounds like a hoax doesn't it? Well, it's not. This worm is real and takes advantage of a flaw in Windows. Microsoft released a patch for it back in October, and you would have already installed it if you have automatic updates turned on. You can install the patch manually by searching Microsoft.com for kb958644 if you don't use the automatic function.

Anyway, this brings me to the topic of this week's column. Most of you have already heard about conficker, but some of you may not know about the Microsoft Windows Malicious Software Removal Tool (MSRT). Now, the MSRT is not, nor is it a substitute for anti-virus software; you still need that.

The MSRT can however remove specific malicious software from your box, and conficker, is one of the things it can remove. A new MSRT is released about once every month via automatic updates. Again, if you don't do auto updates, you can manually download and install the tool.

If you think you may have been exposed to conficker, you can run the MSRT buy clicking start, run and typing mrt in the open box. Click ok to start the tool.

To find conficker, you will need to have the January 2009 version of the tool installed. The date is listed right on the title bar. You must choose the full scan option on the next page. This scan will take some time to complete but it will clean your machine. Remember to install the patch so you don't get infected again!

toddmusseau@gmail.com

Submit a Comment

Submit a Comment

This form is NOT used for emailing the article to a friend. Please use the "Send to a friend" link at the top of the page for that purpose.

The Gulf News is not responsible for posted comments. Please be polite and confine your comments to the subject of the posted story. If you have an account, please sign on to it..

(we keep all emails private)
Agreement

We ask that users remain courteous. You may not post insulting, discriminatory or inappropriate content, which may be removed at our discretion. We are not responsible for user content and opinions. Use of this site as well as content submission & ownership are governed by our Conditions of Use and Privacy Policy.

Member organizations should be non-profit in nature, and promote legal activities. Any organization found promoting illegal activities or commercial products or services will be deleted from the site.

I agree with these conditions.

Advertising

loading...

Newsletter

Please enter your email to receive our free newsletter

Subscribe to news alerts

Gulf News Twitter

Advertising